CRISC Information Technology and Security Practice Question
A risk practitioner is using the FAIR model to quantify cyber risk for a proposed new online payment system. Which factor must be estimated to calculate the probable financial impact of a data breach?
⚠ Common exam trap
CRISC often tests the distinction between frequency factors (TEF, ARO) and magnitude factors (Loss Magnitude, SLE) in quantitative risk models — candidates who see 'financial impact' and grab a familiar acronym like ARO or a severity score like CVSS fall into the trap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loss magnitude
In the FAIR (Factor Analysis of Information Risk) model, risk is quantified as the probable frequency and probable magnitude of future loss. To calculate the probable financial impact of a data breach, the practitioner must estimate Loss Magnitude — the monetary value of the loss event, typically broken down into primary loss (response, replacement, fines) and secondary loss (reputation, legal, competitive advantage). Threat event frequency drives the probability side of the equation, not the impact side.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat event frequency
Why it's wrong here
Threat event frequency estimates how often threat agents act against the asset, feeding loss event frequency rather than the probable financial impact of a breach. It would be correct when calculating how often loss events occur, not the magnitude of resulting financial loss.
- ✓
Loss magnitude
Why this is correct
FAIR quantifies risk as loss event frequency multiplied by loss magnitude. Loss magnitude estimates the probable financial impact of a breach, covering primary and secondary response, replacement and reputational costs, which is exactly the factor needed for the impact calculation.
- ✗
Vulnerability severity score
Why it's wrong here
A vulnerability severity score rates technical weakness, not the probable financial impact of a breach; FAIR requires primary and secondary loss estimates. It would be correct for prioritising patch remediation, not for quantifying monetary loss magnitude in a risk analysis.
- ✗
Annualized rate of occurrence
Why it's wrong here
Annualised rate of occurrence measures expected event frequency per year, which drives loss event frequency, not the probable financial impact of a breach. It would be correct when estimating how many loss events occur annually, not the monetary magnitude of a single breach.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.